-
Feature
-
Resolution: Done
-
Blocker
-
None
-
BU Product Work
Story: As a Quay administrator I like to be able to forward all logs to a Splunk deployment so that I can do for further analysis and offload the internal database.
Why is this important: Quay supports ElasticSearch as a log forward target. Splunk is another stream/log data analysis solution common in enterprise deployments and usually deployed as an alternative to ElasticSearch rather than in parallel.
Acceptance criteria:
- all logs relevant for audits are forwarded to Splunk Enterprise
- no additional plugins are required to be installed on the Splunk side
- SSL communication with Splunk
- Token-based auth with Splunk